Overview
The Overview tab is the first page of Intelligence. It answers three questions at a glance: what in your environment matches threat intel right now, whether your intel feeds are healthy, and which threats are relevant to you.
Intelligence is in beta, and access is by request. It may not be enabled for your organization.
Open the Overview
Click Intelligence in the navigation menu. The Overview tab opens first. The numbers cover the scope you picked in the Scope selector.
Pick a time range
The menu at the top right sets the time range for matches: Last 24 hours (the default), Last 7 days or Last 30 days. The range is kept in the page address, so a link you share opens with the same range.
Headline tiles
| Tile | What it shows | Click to open |
|---|---|---|
| Matches | How many times an indicator from your intel was seen in your data during the time range, and how many of those were high confidence. | Indicators, filtered to sighted indicators |
| Active indicators | Indicators that are currently active across the feeds you can see, with how many were added and how many expired today. | Indicators |
| Feeds healthy | Healthy feeds out of all your feeds, and how many are stale or failing. The dot is green when all are healthy, yellow when one is stale, and red when one is failing. | Feeds |
| Detections live | Detection rules that are on, and how many run in shadow. | Detections, filtered to rules that are on |
| ATT&CK coverage | The share of ATT&CK techniques used by threats relevant to you that have a live detection. Shows "—" until a threat has been scored as relevant. | Coverage |
A feed is stale when it hasn't succeeded for more than twice its polling interval (24 hours for bulk feeds). It is failing when its last run failed.
Cards
Needs attention
The things most worth a look, highest first. Items are ranked by indicator confidence, the value of the affected asset and how recent they are. Each item has a coloured dot for its severity (critical, high, medium or low) and links to where you can act on it.
| Item | Example |
|---|---|
| An indicator seen in your environment | "185.220.101.4 seen on 3 endpoints" |
| A known exploited vulnerability on software you own | "KEV CVE-… on 14 owned hosts" |
| Hits from a retro-hunt | "Retro-hunt: 2 hits for …" |
| A shadow rule that fires a lot | "Rule … fired 212× in shadow" |
| A feed that is failing | The feed and its error |
When there is nothing to flag, the card says "Nothing needs attention right now."
Threats relevant to you
The three threats (actors, malware and campaigns) that overlap most with your stack, based on the products you have connected, the software you own and your detections. Each shows why it is relevant and one fact to act on: how many of its techniques you don't cover yet, how many of its CVEs you own, or "low overlap". Click a threat to open it on the Threats tab, or All threats to see the full list.
Feed health
Your feeds, problems first. Each shows whether it is shared or private (and TAXII or MISP), how many indicators it adds per day, how many matches it produced this week and its largest overlap with another feed. A failing feed shows its error instead. The time on the right is its last successful run. Click a feed to open it on the Feeds tab.
Coverage
A small ATT&CK map: one row per tactic, one square per technique. Darker squares have a live detection, lighter ones are covered only by hunts or shadow rules, and grey ones have no coverage. Under the map are the counts. Click Open coverage for the full map. See Coverage.
Coverage is measured per organization. If your scope is Personal, the card asks you to switch to an organization.
If a card can't load
Each card loads on its own. If one fails, it shows the error and a Retry button, and the rest of the page keeps working.
Next steps
- Coverage — the full ATT&CK coverage map